CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-66310
7.7 HIGH

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

Aug 4, 2026
CVE-2026-65802
7.4 HIGH

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

Aug 4, 2026
CVE-2026-62870
8.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

Aug 4, 2026
CVE-2026-67978
7.5 HIGH

An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN …

Aug 3, 2026
CVE-2026-48399
7.5 HIGH

Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could …

Aug 3, 2026
CVE-2026-67977
7.5 HIGH

An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Aug 3, 2026
CVE-2026-67973
7.5 HIGH

An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.

Aug 3, 2026
CVE-2026-10849
8.2 HIGH

The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). …

Aug 3, 2026
CVE-2026-69246
7.2 HIGH

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host …

Aug 3, 2026
CVE-2026-67976
7.5 HIGH

The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Denial of Service (DoS) via …

Aug 3, 2026
CVE-2026-52521
8.1 HIGH

A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the CommentBat feature.

Aug 3, 2026
CVE-2026-41447
7.8 HIGH

FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in …

Aug 3, 2026
CVE-2026-18733
8.8 HIGH

A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands …

Aug 3, 2026
CVE-2026-18647
7.3 HIGH

A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue affects the function isValidTLD of the file /backend/functions/src/cloud-functions/crawler.ts of the component …

Aug 3, 2026
CVE-2026-69185
7.5 HIGH

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait …

Aug 3, 2026
CVE-2026-68981
7.5 HIGH

Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum …

Aug 3, 2026
CVE-2026-67599
7.2 HIGH

ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands by submitting unsanitized input …

Aug 3, 2026
CVE-2026-67598
7.4 HIGH

Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM …

Aug 3, 2026
CVE-2026-18641
7.3 HIGH

A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.sbr.fort.foreignDP.DpLoginController of the …

Aug 3, 2026
CVE-2026-59913
7.8 HIGH

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local …

Aug 3, 2026
CVE-2026-59912
7.8 HIGH

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could …

Aug 3, 2026
CVE-2026-61524
7.2 HIGH

WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated administrators to achieve remote code execution by …

Aug 3, 2026
CVE-2026-61523
7.2 HIGH

WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arbitrary PHP code by submitting malicious …

Aug 3, 2026
CVE-2026-69152
7.5 HIGH

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while …

Aug 3, 2026
CVE-2026-67611
8.1 HIGH

OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant …

Aug 3, 2026
CVE-2026-67610
8.1 HIGH

OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with …

Aug 3, 2026
CVE-2026-61372
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena Fuseki: through 6.1.0. Users …

Aug 3, 2026
CVE-2026-41453
8.8 HIGH

Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL …

Aug 3, 2026
CVE-2026-39931
7.2 HIGH

OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that allows administrators with admin or super ACL privileges to …

Aug 3, 2026
CVE-2026-18718
7.0 HIGH

Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra …

Aug 3, 2026
CVE-2026-18607
8.8 HIGH

A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 …

Aug 3, 2026
CVE-2026-18606
7.8 HIGH

A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)\Razer\RzUpdateEngineService\RzUpdateService.exe of the …

Aug 3, 2026
CVE-2026-18605
7.0 HIGH

A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown function in the library AppCheckD.sys of the component Kernel Mini-Filter …

Aug 3, 2026
CVE-2026-18568
7.5 HIGH

XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check. …

Aug 3, 2026
CVE-2026-67609
7.8 HIGH

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalation vulnerability that allows attackers with access to …

Aug 3, 2026
CVE-2026-69097
7.0 HIGH

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers …

Aug 3, 2026
CVE-2026-69096
8.8 HIGH

OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's …

Aug 3, 2026
CVE-2026-69095
7.5 HIGH

OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured …

Aug 3, 2026
CVE-2026-69091
7.5 HIGH

Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logic in modules/forum.php fails to …

Aug 3, 2026
CVE-2026-69089
7.5 HIGH

Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image argument to RocketTheme\Toolbox\ResourceLocator\UniformResourceLocator::findResource(). Because the file:// scheme branch only lexically …

Aug 3, 2026
CVE-2026-69088
8.1 HIGH

Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint dynamic-field directives because Blueprint::isSafeDynamicCall() only applies its dangerous-callable denylist …

Aug 3, 2026
CVE-2026-69086
7.7 HIGH

SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to construct traversal paths that …

Aug 3, 2026
CVE-2026-68587
8.6 HIGH

SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access checks. Anonymous …

Aug 3, 2026
CVE-2026-68586
8.6 HIGH

SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). While the corresponding backlink list endpoints filter …

Aug 3, 2026
CVE-2026-68584
8.6 HIGH

SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting …

Aug 3, 2026
CVE-2026-67608
7.2 HIGH

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated …

Aug 3, 2026
CVE-2026-18642
7.8 HIGH

Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection. This issue affects eta-otp-lock: before 1.0.4.

Aug 3, 2026
CVE-2026-18600
8.8 HIGH

A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.switch_status of the file /usr/lib/oui-httpd/rpc/network of the component Network Lua …

Aug 3, 2026
CVE-2026-18092
8.1 HIGH

Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the …

Aug 3, 2026
CVE-2026-18089
7.5 HIGH

Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured. …

Aug 3, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.